Showing posts with label hacktivism. Show all posts
Showing posts with label hacktivism. Show all posts

Wednesday, March 21, 2018

An Overview of Middle Eastern and North African Hacking Activity

Cybercriminals in the Middle East/North Africa (MENA) region are some of the most cooperative and united group of hackers in the world when their goal is to attack the West. Hacktivists collaborate for finanical and political gain, as well as for religious righteousness. Cyber prevention is often difficult because many cyber security experts do not always understand Arabic hacker websites, databases and infrastructure. Wapack Labs believe MENA actors will remain active and successful in various cyber campaigns against the West until the West attains a better understanding of the region’s language, culture, and religions...READ MORE

Wapack Labs has cataloged and reported on cyber threats operating in the Middle East/North Africa in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Thursday, March 1, 2018

Bosnia and Herzegovina Cyber Profile

Bosnia and Herzegovina is a country in Southeastern Europe formerly under the Republic of Yugoslavia. After the dissolution of Yugoslavia, Bosnia and Herzegovina has experienced infighting of ethnically and religiously motivated hacktivist groups, as well as commercially motivated hackers. Current cyberlaws are not fully enacted, yet the country completely cooperates to fight cybercrime. Bosnian hackers use Bosnian, Serbian, German, English, and other languages to communicate. Due to recent international arrests, many Bosnian groups have been driven underground. The current Western threat of Bosnian hackers is low, based on our current data...READ MORE

Wapack Labs has cataloged and reported on international cyber profiles in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Friday, January 5, 2018

Iranian Protests and Cyber Hacktivism

Wapack Labs analysts have been monitoring the recent demonstrations in Iran involving discontent toward the Islamic Republic seated in the aftermath of the 1979 Revolution. Iranian dissidents and activists took to the streets by the thousands, chanting slogans like “We don’t want an Islamic Republic” and “Death to the dictator”, as they tore down pictures of Supreme Leader Khamenei and set fire to the Governor’s office. Protests began in the second most populous city in Iran, Mashhad, built centered on the Holy Shrine of Imam Reza, which remains a place for religious pilgrimage. By day two, the protests, with the help of the instant messaging service ‘Telegram’, gained momentum reaching the very western city of Kermanshah. As the Iranian government took steps to block media platforms like Instagram, Twitter, and Telegram, the third day of protests had already spread from the northern city of Tabriz to the southern port city of Bandar Abbas...READ MORE
 
Wapack Labs has cataloged and reported on cyber hacktivism in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Thursday, January 4, 2018

The Iranian Cyber Evolution: RATs, Backdoors, and Droppers

Wapack Labs has been monitoring Iranian cyber activity for several years, specifically the evolving OilRig and Greenbug campaigns. Their adoption of a cyber operational paradigm involving both cyber hacktivism and cyber espionage tactics resembles cyber activity patterns employed by Chinese APT groups, whereby different groups perform different campaigns, with multiple teams conducting separate phases of a cyber campaign. With President Trump’s refusal to re-certify Iran’s compliance with the 2015 Iran nuclear agreement, Wapack analysts are researching the continued efforts of Iranian-backed cyber threats in order to detect and defend against next moves. 

One common attribute is that they all engage in prolonged reconnaissance campaigns of their targets; at times lasting over a year. Greenbug, a cyber-espionage group with suspected Iranian ties, has been dynamically progressing in such campaigns. In August 2017, a Greenbug tool, dubbed ISMAgent (an ISMDoor variant), resurfaced in the wild to harvest account credentials. Wapack Labs discovered evidence of ISMDoor variants relying on the VB:Trojan.Valyria (possibly Clayside) for delivery, linking Greenbug to another group of Iranian actors known as OilRig. Wapack Labs assesses with moderate confidence that recent activity involving ISMDoor is an indicator of the ramping up of another cyber campaign cycle...READ MORE

Wapack Labs has cataloged and reported on Iranian cyber activity in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

Thursday, December 21, 2017

Dead Russian Social Media Accounts Hacked

Social media accounts originally belonging to the deceased were recently observed promoting pro-Putin messages in Russia. The Russian social network, VK (formerly Vkontakte), reported that accounts were hacked. Social media accounts whose owners are no longer living and other abandoned accounts with weak password security were used in this campaign. Because they were deceased or abandoned accounts, account owners could not react to possible security warnings. Social media networks have different processes for deactivating deceased users. Abandoned accounts may be especially vulnerable to brute force attacks and may later be used in malware or disinformation campaigns. This use of hacked accounts poses a risk of international-level account hijacking on a variety of social media networks...READ MORE

Wapack Labs has cataloged and reported on social media hijacking in the past. An archive of related reporting can be found in the Red Sky Alliance portal.

WWW.WAPACKLABS.COM

Wednesday, October 18, 2017

Iranian Cyber Campaign Evolutions – The Next Wave: Greenbug and Ismdoor

Greenbug is an Advanced Persistent Threat (APT) cyber-espionage group with suspected Iranian ties. In August 2017, a Greenbug tool dubbed Ismdoor resurfaced in the wild. The malware possesses many reconnaissance capabilities, and in August of 2016 was deployed to harvest account credentials prior to an attack against Saudi Arabian infrastructure. Wapack Labs assesses with moderate confidence that the presence of Ismdoor is an indicator that Greenbug may be performing reconnaissance for a future campaign. While the Greenbug group is not directly affecting the membership, the targeting of Middle Eastern gas and energy companies affects multiple supply chains with repercussions for U.S. and Allied interests in the region. Wapack Labs’ analysts have also detected an evolution in Iranian cyber campaigns indicating likely adoption of cyber espionage and cyber hacktivism models similar to those employed by the Chinese APT groups, whereby different groups are utilized in different campaigns and multiple teams conduct separate phases of a cyber campaign. The Iranian originated campaigns, similar to the Chinese APT model, are also conducted in waves. The resurgence of Greenbug and Ismdoor indicate another Iranian based cyber campaign cycle is being initiated in the Middle East...READ MORE

Wapack Labs has cataloged and reported on APT groups and campaigns in the past. An archive of related reporting can be found in the Red Sky Alliance portal. 

Friday, October 28, 2016

Gaming Platforms Attacked, Customer Info Targeted

Cyber hacktivism, threat actor group activity, and online gaming often go hand-in-hand because many threat actors also play online games. The combination of these activities can often result in the theft of credit card data and other forms of Personally Identifiable Information (PII) from online gaming accounts. In previous instances, threat actor groups that have attacked gaming and entertainment companies were later identified as having launched similarly styled attacks at financial institutions. Thus, knowledge of attacks against gaming and entertainment companies has the potential to provide future insight in to the Tactics, Techniques, and Procedures (TTPs) of attacks that may evolve to target the financial sector directly.

Key Findings:
  • Compromise of a gaming account can result in theft of credit card data and other forms of PII because many gaming services require payment for additional Downloadable Content (DLC), and credit card information is sometimes mandatory for creating an account.
  • Malware samples that were found inside Sony’s network in the U.S. were reported to share unique traits similar to the malware used to target the SWIFT network.
  • Threat actor groups Anonymous, Lizard Squad, LulzSec, and PoodleCorp have all attacked online gaming and entertainment companies as well as financial institutions.
  • Awareness and knowledge of threat actor groups attacking gaming and entertainment companies can provide potential insight into similarly styled attacks that may take place against the financial sector. 
  • Phantom Squad is one such threat actor group that has attacked gaming and entertainment companies but has not yet, at least, attacked financial institutions.


Publication date:                   26 October 2016
Handling requirements:       Traffic light protocol (TLP) AMBER.
Attribution/Threat Actors:  Criminal
Actor Type:                           Adversary capabilities have been assessed as Tier I-III*
Companies Targeted:           Online gaming and Entertainment Companies, Financial Sector

Past Reporting:                     DOC-3970, 3964, 1858, 2594, 4170, 1412

*Practitioners with between a novice and moderate depth of experience who rely on currently available tools and are also capable of discovering vulnerabilities.

The full attribution report has been published in its entirety in the Red Sky Alliance portal.  For more information please contact the lab directly at 844-4-WAPACK, 603-606-1246, or feedback@wapacklabs.com.

About Wapack Labs

Wapack Labs, located in New Boston, NH is a Cyber Threat Analysis and Intelligence organization supporting the Red Sky Alliance, the FS-ISAC and individual organizations by offering expert level targeted intelligence analysis answering some of the hardest questions in Cyber.  Wapack Labs’ engineers, researchers and analysts use deep analysis techniques and visualization to design and deliver transformational cyber-security analysis tools that fuse open source and proprietary information.  The intelligence derived from these tools and techniques serve as the foundation of Wapack Labs’ information reporting to the cyber-security teams of its customers and industry partners located around the world.